TWM648486U - Telecommunication authentication service system - Google Patents

Telecommunication authentication service system Download PDF

Info

Publication number
TWM648486U
TWM648486U TW112205403U TW112205403U TWM648486U TW M648486 U TWM648486 U TW M648486U TW 112205403 U TW112205403 U TW 112205403U TW 112205403 U TW112205403 U TW 112205403U TW M648486 U TWM648486 U TW M648486U
Authority
TW
Taiwan
Prior art keywords
authentication
module
user
biometric
encryption
Prior art date
Application number
TW112205403U
Other languages
Chinese (zh)
Inventor
廖晨楓
Original Assignee
廖晨楓
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 廖晨楓 filed Critical 廖晨楓
Priority to TW112205403U priority Critical patent/TWM648486U/en
Priority to JP2023002658U priority patent/JP3243831U/en
Publication of TWM648486U publication Critical patent/TWM648486U/en

Links

Images

Landscapes

  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Exchange Systems With Centralized Control (AREA)
  • Meter Arrangements (AREA)

Abstract

一電信認證服務系統,包括:一多重認證模組,用於進行多重認證過程,要求用戶提供至少兩種不同的認證方式,其中之一為生物特徵資料;一加密模組,包括一通訊元件,該加密模組經由該通訊元件與用戶的行動通訊裝置及服務提供者電性連接,該加密模組用於保護用戶行動通訊裝置與服務提供者之間的通訊,保護在多重認證過程中傳輸的敏感資料;一裝置安全模組,電性連接至該加密模組,該裝置安全模組用於定期對用戶的行動通訊裝置進行安全更新和掃描;還有一風險基礎認證模組,用於分析用戶行為和交易模式,以識別潛在風險,必要時提示至少一額外認證因素。其中,多重認證模組包括生物特徵認證模組,設置為收集、儲存和認證用戶的生物特徵資料。 A telecommunications authentication service system, including: a multi-authentication module for performing a multi-authentication process, requiring users to provide at least two different authentication methods, one of which is biometric data; an encryption module, including a communication component , the encryption module is electrically connected to the user's mobile communication device and the service provider through the communication element. The encryption module is used to protect the communication between the user's mobile communication device and the service provider, and to protect the transmission during the multi-factor authentication process. sensitive information; a device security module, electrically connected to the encryption module; the device security module is used to regularly perform security updates and scans on the user's mobile communication device; and a risk-based authentication module for analysis User behavior and transaction patterns to identify potential risks and prompt at least one additional authentication factor if necessary. Among them, the multi-factor authentication module includes a biometric authentication module, which is configured to collect, store and authenticate the user's biometric information.

Description

電信認證服務系統 Telecommunications certification service system

本新型涉及一種電信安全領域,更具體地說,涉及一個多重認證服務系統,旨在通過利用生物特徵資料和風險基礎認證等安全功能,增強網上交易和服務的安全性。 The invention relates to the field of telecommunications security, and more specifically, to a multi-authentication service system, which aims to enhance the security of online transactions and services by utilizing security functions such as biometric data and risk-based authentication.

隨著數位服務和電子交易的迅速擴展,確保用戶個人和財務資訊的安全和隱私已成為一個日益迫切的需求。傳統的認證方法,例如用戶名稱和密碼的組合,在保護免受精心策劃的網絡攻擊和身份盜竊方面已被證明是不足夠的。因此,多重認證方法已成為一種更強大的解決方案,用於認證用戶的身份和保護敏感交易。 With the rapid expansion of digital services and electronic transactions, ensuring the security and privacy of users' personal and financial information has become an increasingly urgent need. Traditional authentication methods, such as username and password combinations, have proven inadequate in protecting against orchestrated cyberattacks and identity theft. As a result, multi-factor authentication methods have become a more robust solution for authenticating users’ identities and protecting sensitive transactions.

例如,通過物理令牌結合短信發送的一次性密碼已成為一種流行的認證方法。然而,這些密碼容易被惡意軟件或其他攻擊攔截,如SIM卡交換,進而危及用戶的設備或通訊。此外,依賴物理令牌或設備對用戶和服務提供者來說可能很不方便和昂貴,而基於知識的認證因素(例如密碼或安全問題)的有效性可能會因為用戶不當的操作或資料外洩而受損。 For example, one-time passwords sent via physical tokens combined with text messages have become a popular authentication method. However, these passwords can be easily intercepted by malware or other attacks, such as SIM swapping, compromising the user's device or communications. Additionally, relying on physical tokens or devices can be inconvenient and expensive for users and service providers, while the effectiveness of knowledge-based authentication factors (such as passwords or security questions) can be compromised by inappropriate user actions or data leakage. And damaged.

此外,現有的認證系統通常採用種標準化的驗證方法或系統,適用於所有用戶和交易,可能無法充分滿足不同用戶和交易的不同安全需求和風險概況。因此,需要一個改進的電信認證服務系統,提供增強的安全功能和適應性認證機制,更好地保護用戶和服務提供者免受不斷發展的威脅和漏洞的侵害。 In addition, existing authentication systems usually adopt a standardized verification method or system that is suitable for all users and transactions, which may not fully meet the different security needs and risk profiles of different users and transactions. Therefore, there is a need for an improved telecommunications authentication service system that provides enhanced security features and adaptive authentication mechanisms to better protect users and service providers from evolving threats and vulnerabilities.

本新型之目的在於提供一整合多重認證、生物特徵資料認證、風險基礎認證等安全功能的電信認證服務系統,來解決上述限制。 The purpose of this new model is to provide a telecommunications authentication service system that integrates multiple authentication, biometric data authentication, risk-based authentication and other security functions to solve the above limitations.

基於上述目的與其他目的,本新型提供一種電信認證服務系統,與多個用戶的行動通訊裝置及至少一服務提供者電性連接,其包括以下元件:一個多重認證模組,用於進行多重認證過程,要求用戶提供至少兩種不同的認證方式,其中之一為生物特徵資料;一個加密模組與所述用戶的該行動通訊裝置及該服務提供者電性連接,加密模組用於保護用戶行動通訊裝置與服務提供者之間的通訊,保護在多重認證過程中傳輸的敏感資料;一個裝置安全模組,電性連接至該加密模組,該裝置安全模組用於定期對用戶的行動通訊裝置進行安全更新和掃描,確保多重認證過程中生物特徵認證模組所收集的生物特徵資料的完整性;還有一個風險基礎認證模組,電性連接至該加密模組,該風險基礎認證模組用於分析用戶行為和交易模式,以識別潛在風險,必要時提示至少一個額外認證因素。其中,多重認證模組包括生物特徵認證模組,設置為收集、儲存和認證至少一種用戶生物特徵資料,為多重認證過程提供額外的安全層級。而且,多重認證模組電性連接至該加密模組。 Based on the above and other purposes, the present invention provides a telecommunications authentication service system that is electrically connected to mobile communication devices of multiple users and at least one service provider. It includes the following components: a multi-authentication module for performing multiple authentications. The process requires the user to provide at least two different authentication methods, one of which is biometric data; an encryption module is electrically connected to the user's mobile communication device and the service provider, and the encryption module is used to protect the user Communication between the mobile communication device and the service provider protects sensitive information transmitted during the multi-factor authentication process; a device security module is electrically connected to the encryption module. The device security module is used to regularly monitor the user's actions. The communication device performs security updates and scans to ensure the integrity of the biometric data collected by the biometric authentication module during the multi-factor authentication process; there is also a risk-based authentication module electrically connected to the encryption module, and the risk-based authentication module The module is used to analyze user behavior and transaction patterns to identify potential risks and prompt at least one additional authentication factor when necessary. Among them, the multi-factor authentication module includes a biometric authentication module, which is configured to collect, store and authenticate at least one user biometric information to provide an additional level of security for the multi-factor authentication process. Moreover, the multi-factor authentication module is electrically connected to the encryption module.

在上所述之電信認證服務系統中,該多重認證模組被設置要求用戶提供以下組合:由選自密碼、個人身份識別碼或安全問題群組中的一第一特徵資料,選自物理令牌、行動通訊裝置相關認證或加密金鑰群組中的一第二特徵資料,並且至少一項由生物特徵認證模組收集的生物特徵資料。 In the above-mentioned telecommunications authentication service system, the multi-factor authentication module is configured to require the user to provide the following combination: a first characteristic data selected from a password, a personal identification code or a security question group, a physical token selected from a second characteristic data in the authentication or encryption key group related to the brand or mobile communication device, and at least one piece of biometric data collected by the biometric authentication module.

在上所述之電信認證服務系統中,生物特徵認證模組設置為收集和認證從選自由指紋、臉部識別、語音識別和虹膜識別所組成的群組中的生物特徵資料。 In the above-mentioned telecommunications authentication service system, the biometric authentication module is configured to collect and authenticate biometric data selected from a group consisting of fingerprints, facial recognition, voice recognition and iris recognition.

在上所述之電信認證服務系統中,加密模組利用端對端加密來保護該用戶的該行動通訊裝置和該服務提供者之間的通訊。 In the above-mentioned telecommunications authentication service system, the encryption module uses end-to-end encryption to protect the communication between the user's mobile communication device and the service provider.

在上所述之電信認證服務系統中,風險基礎認證模組設置為根據識別出的至少一潛在風險,包括一不尋常的用戶行為或一不規則的交易模式,提示用戶提供額外認證因素。 In the above-mentioned telecommunications authentication service system, the risk-based authentication module is configured to prompt the user to provide additional authentication factors based on at least one potential risk identified, including an unusual user behavior or an irregular transaction pattern.

在上所述之電信認證服務系統中,額外認證因素包括由生物特徵認證模組認證的生物特徵資料。 In the above-mentioned telecommunications authentication service system, additional authentication factors include biometric information authenticated by the biometric authentication module.

本新型之電信認證服務系統,提供了多重認證模組、生物特徵認證模組、加密模組、裝置安全模組和風險基礎認證模組。在這些組件共同工作下,提供一個全面且適應性強的安全解決方案,可以有效地保護用戶和服務提供者免受未經授權的訪問、資料外洩和其他網絡威脅。 This new type of telecommunications authentication service system provides multiple authentication modules, biometric authentication modules, encryption modules, device security modules and risk-based authentication modules. These components work together to provide a comprehensive and adaptable security solution that can effectively protect users and service providers from unauthorized access, data leakage and other cyber threats.

為讓本新型之上述特徵和優點能更明顯易懂,下文特舉較佳實施例,並配合所附圖式,作詳細說明如下。 In order to make the above-mentioned features and advantages of the present invention more obvious and easy to understand, preferred embodiments are cited below and described in detail with reference to the attached drawings.

100:電信認證服務系統 100:Telecom authentication service system

110:多重認證模組 110:Multiple authentication module

120:生物特徵認證模組 120:Biometric authentication module

130:加密模組 130: Encryption module

140:裝置安全模組 140:Device security module

150:風險基礎認證模組 150: Risk based certification module

10:用戶 10:User

20:服務提供者 20:Service provider

圖1所繪示為本新型之電信認證服務系統的示意圖。 Figure 1 shows a schematic diagram of the new telecommunications authentication service system.

圖2所繪示本新型之用戶、電信認證服務系統、服務提供者的應用示意圖。 Figure 2 shows a schematic diagram of the application of users, telecommunications authentication service systems, and service providers of the present invention.

請參閱圖1,圖1所繪示為本新型之電信認證服務系統的示意圖。電信認證服務系統旨在通過納入多重認證、生物特徵資料認證、風險基礎認證和其他高級安全功能,增強網上交易和服務的安全性。該電信認證服務系統100包括一多重認證模組110、一生物特徵認證模組120、一加密模組130、一裝置安全模組140、與一風險基礎認證模組150。其中,多重認證模組110設置為要求用戶 提供至少兩種不同形式的認證,其中之一是由生物特徵認證模組120認證的生物特徵資料。多重認證模組可以支援其他多種認證因素,如密碼、PIN、安全問題、物理令牌(physical token)、行動通訊裝置相關認證和加密金鑰等。 Please refer to Figure 1. Figure 1 shows a schematic diagram of the new telecommunications authentication service system. The telecommunications authentication service system aims to enhance the security of online transactions and services by incorporating multi-factor authentication, biometric authentication, risk-based authentication and other advanced security features. The telecommunications authentication service system 100 includes a multi-factor authentication module 110, a biometric authentication module 120, an encryption module 130, a device security module 140, and a risk-based authentication module 150. Among them, the multi-factor authentication module 110 is set to require the user At least two different forms of authentication are provided, one of which is biometric data authenticated by the biometric authentication module 120 . Multi-factor authentication modules can support a variety of other authentication factors, such as passwords, PINs, security questions, physical tokens, mobile communication device-related authentication and encryption keys, etc.

生物特徵認證模組120用於收集、存儲和認證用戶的生物特徵資料,為多重認證模組110所進行的多重認證過程提供額外的安全層級。生物特徵認證模組120可以支援多種生物特徵資料,包括指紋、臉部識別、語音識別和虹膜識別等。 The biometric authentication module 120 is used to collect, store and authenticate the user's biometric information, providing an additional level of security for the multi-factor authentication process performed by the multi-factor authentication module 110 . The biometric authentication module 120 can support a variety of biometric data, including fingerprints, facial recognition, voice recognition, iris recognition, etc.

另外,加密模組130通過使用端對端加密來保護用戶的一行動通訊裝置和服務提供者之間的通訊,確保在多重認證過程中傳輸的敏感資料得到保護。此外,裝置安全模組140設置為強制執行定期的安全更新和掃描,確保多重認證過程中生物特徵認證模組120收集的生物特徵資料的完整性。而且,風險基礎認證模組150分析用戶行為和交易模式,以識別潛在風險。風險基礎認證模組150在必要時提示用戶提供額外認證因素,包括由生物特徵認證模組認證的生物特徵資料。 In addition, the encryption module 130 protects communications between a user's mobile communication device and the service provider by using end-to-end encryption to ensure that sensitive data transmitted during the multi-factor authentication process is protected. In addition, the device security module 140 is configured to enforce regular security updates and scans to ensure the integrity of the biometric data collected by the biometric authentication module 120 during the multi-factor authentication process. Furthermore, the risk-based authentication module 150 analyzes user behavior and transaction patterns to identify potential risks. The risk-based authentication module 150 prompts the user to provide additional authentication factors when necessary, including biometric information authenticated by the biometric authentication module.

以下,將對多重認證模組110中的各元件進行更詳細的介紹,首先將介紹多重認證模組110。多重認證模組110通過要求用戶提供至少兩種不同形式的認證,增強安全性。多重認證模組110所需的各種認證因素,可以分為三個主要類別:一第一特徵資料,為用戶所知道的內容。這個類別包括基於知識的認證因素,如密碼、個人識別號碼和安全問題。這些因素依賴用戶回想起特定資料,這些資料對他人不易獲得;一第二特徵資料,為用戶所擁有的物品。這個類別包括基於物品擁有的認證因素,如物理令牌、行動通訊裝置相關認證和加密鑰匙,這些因素要求用戶可以物理訪問特定的物品或設備,以作為其身份證明; 一第三特徵資料,是用戶的至少一生物特徵資料。這個類別涉及基於繼承的認證因素,這些因素由生物特徵認證模組120收集的生物特徵資料來表示。生物特徵資料的例子包括指紋、面部識別、語音識別和虹膜識別。多重認證模組110結合這些認證因素,創建了一個強大而安全的認證過程,確保用戶必須提供多種身份認證證明,才能訪問網上交易和服務。 Below, each component in the multi-factor authentication module 110 will be introduced in more detail. First, the multi-factor authentication module 110 will be introduced. Multi-factor authentication module 110 enhances security by requiring users to provide at least two different forms of authentication. The various authentication factors required by the multi-authentication module 110 can be divided into three main categories: 1. First characteristic information, which is what the user knows. This category includes knowledge-based authentication factors such as passwords, PINs, and security questions. These factors rely on the user recalling specific information that is not readily available to others; - secondary characteristic information, which is items owned by the user. This category includes authentication factors based on item possession, such as physical tokens, mobile communication device-related authentication and encryption keys, which require users to have physical access to a specific item or device as proof of their identity; A third characteristic data is at least one biometric data of the user. This category relates to inheritance-based authentication factors represented by the biometric data collected by the biometric authentication module 120 . Examples of biometric data include fingerprints, facial recognition, voice recognition, and iris recognition. The multi-factor authentication module 110 combines these authentication factors to create a strong and secure authentication process, ensuring that users must provide multiple identity authentication proofs to access online transactions and services.

上述中,行動通訊裝置相關認證例如是向用戶的行動通訊裝置發送一次性密碼或推送通知。然後,使用者需要輸入一次性密碼或確認推送通知以認證其身份。或者,行動通訊裝置還可以存儲加密密鑰或數位證書,實現安全通訊,為身份認證過程添加了另一層安全性。另外,物理令牌是指用戶擁有的小型硬體裝置,其通常會生成一唯一且有時間限制的代碼或存儲一個加密密鑰,該加密密鑰與其他身份驗證方法(例如密碼或PIN)結合使用,以驗證用戶的身份。 In the above, the authentication related to the mobile communication device is, for example, sending a one-time password or a push notification to the user's mobile communication device. The user then needs to enter a one-time password or confirm a push notification to authenticate their identity. Alternatively, mobile communication devices can also store encryption keys or digital certificates to enable secure communications, adding another layer of security to the identity authentication process. Alternatively, a physical token is a small hardware device owned by the user that typically generates a unique and time-limited code or stores an encryption key that is combined with other authentication methods such as a password or PIN Used to verify the user's identity.

本新型之多重認證模組110的獨特之處之一在於與生物特徵認證模組120的整合。這種整合允許電信認證服務系統100利用生物特徵資料作為所需的認證因素之一,提供一種更安全且用戶友好的方法,認證用戶身份。生物特徵認證模組120收集、存儲和認證用戶的生物特徵資料,例如指紋、面部識別、語音識別或虹膜識別。當啟動多重認證過程時,生物特徵認證模組120被提示認證用戶的生物特徵資料,作為整個認證過程的一部分。生物特徵認證模組120基於用戶獨特的生物特徵資料進行身份認證,故其提供了一種安全且易於使用的方式。生物特徵認證模組120使用各種傳感器和輸入設備(例如指紋掃描器、面部識別攝像頭、語音識別麥克風或虹膜識別攝像頭)收集用戶的生物特徵資料,然後將資料進行處理,轉換為可以用於後續認證的數位格式。一旦生物特徵資料被收集和數位化,它就會被安全地儲存在資料庫或其他適當的儲存媒介中。須注意,生物特徵資料的儲存必須遵守嚴格的隱私和資料安全指導方針,以保護用戶的個人資訊不受未經授權的訪問或誤用。之後,當用戶啟動多重身 份認證過程時,生物特徵認證模組120會提示用戶將生物特徵資料與儲存的生物特徵資料進行認證,這個認證過程通常涉及比對身份認證過程中捕獲的實時生物特徵資料與儲存的生物特徵資料以確認是否匹配。 One of the unique features of the new multi-factor authentication module 110 is its integration with the biometric authentication module 120 . This integration allows the telecommunications authentication service system 100 to utilize biometric data as one of the required authentication factors, providing a more secure and user-friendly method to authenticate a user's identity. The biometric authentication module 120 collects, stores and authenticates the user's biometric information, such as fingerprint, facial recognition, voice recognition or iris recognition. When the multi-factor authentication process is initiated, the biometric authentication module 120 is prompted to authenticate the user's biometric information as part of the entire authentication process. The biometric authentication module 120 performs identity authentication based on the user's unique biometric information, so it provides a safe and easy-to-use method. The biometric authentication module 120 uses various sensors and input devices (such as fingerprint scanners, facial recognition cameras, voice recognition microphones, or iris recognition cameras) to collect the user's biometric information, and then processes the data and converts it into information that can be used for subsequent authentication. digital format. Once biometric data is collected and digitized, it is securely stored in a database or other appropriate storage medium. It should be noted that the storage of biometric data must comply with strict privacy and data security guidelines to protect users' personal information from unauthorized access or misuse. Later, when the user starts the multiple avatar During the identity authentication process, the biometric authentication module 120 will prompt the user to authenticate the biometric data with the stored biometric data. This authentication process usually involves comparing the real-time biometric data captured during the identity authentication process with the stored biometric data. to confirm the match.

此外,使用生物特徵資料進行身份認證引發了一些隱私和資料安全問題,必須由生物特徵認證模組120解決,以確保保護用戶個人資料的安全。因此,有一些關鍵因素必須考慮。舉例來說,生物特徵資料必須以安全方式存儲,使用加密和其他資料安全措施,以防止未經授權的訪問、資料泄露或其他潛在威脅。此外,生物特徵認證模組120應僅收集和存儲執行身份認證過程所需的最小生物特徵資料,減少資料泄露或隱私侵犯的潛在影響。另外,必須實施嚴格的訪問控制措施,以確保只有授權的人員和系統可以訪問生物特徵資料,防止未經授權的訪問或濫用。而且,生物特徵認證模組120還必須遵守相關的隱私法規和指南,例如歐盟的《通用資料保護條例》(GDPR)或其他適用的資料保護法律,以確保合法和道德的處理用戶個人資料。 In addition, the use of biometric data for identity authentication raises some privacy and data security issues that must be addressed by the biometric authentication module 120 to ensure the security of the user's personal data. Therefore, there are some key factors that must be considered. For example, biometric data must be stored in a secure manner, using encryption and other data security measures to prevent unauthorized access, data disclosure or other potential threats. In addition, the biometric authentication module 120 should only collect and store the minimum biometric information required to perform the identity authentication process, reducing the potential impact of data leakage or privacy invasion. In addition, strict access control measures must be implemented to ensure that only authorized personnel and systems have access to biometric data to prevent unauthorized access or misuse. Moreover, the biometric authentication module 120 must also comply with relevant privacy regulations and guidelines, such as the European Union's General Data Protection Regulation (GDPR) or other applicable data protection laws, to ensure legal and ethical processing of user personal data.

接下來,將介紹加密模組130,其是電信認證服務系統100的重要組成部分,用以確保用戶的行動通訊裝置和服務提供者之間的敏感資料傳輸的安全性。加密模組130的主要功能之一是實現端對端加密,端對端加密提供了以下好處: Next, the encryption module 130 will be introduced, which is an important component of the telecommunications authentication service system 100 and is used to ensure the security of sensitive data transmission between the user's mobile communication device and the service provider. One of the main functions of the encryption module 130 is to implement end-to-end encryption. End-to-end encryption provides the following benefits:

a)資料保護:端對端加密確保在傳輸過程中的資料始終處於加密狀態,防止資料被截取或在傳輸過程中遭到未經授權的訪問。 a) Data protection: End-to-end encryption ensures that data during transmission is always encrypted, preventing data from being intercepted or being accessed without authorization during transmission.

b)隱私:端對端加密在通訊的兩端都進行加密,保護用戶的隱私,確保僅有意圖的接收方才能解密和存取傳輸的資料。 b) Privacy: End-to-end encryption encrypts both ends of the communication to protect user privacy and ensure that only the intended recipient can decrypt and access the transmitted data.

c)身份認證:端對端加密還提供了一定程度的身份認證,因為只有擁有相應加密金鑰的參與方才能建立安全通訊,確認通訊參與方的身份。 c) Identity authentication: End-to-end encryption also provides a certain degree of identity authentication, because only participants with corresponding encryption keys can establish secure communications and confirm the identities of communication participants.

加密模組130利用各種加密協定和演算法來確保用戶的行動通訊裝置和服務提供者之間的通訊安全。這些協定和演算法的選擇基於安全強度、計算效率 和與整個系統架構的兼容性等因素。一些常用的加密協定和演算法包括高級加密標準(Advanced Encryption Standard,AES)、RSA加密、SSL和TLS加密。 The encryption module 130 utilizes various encryption protocols and algorithms to ensure communication security between the user's mobile communication device and the service provider. The selection of these protocols and algorithms is based on security strength, computational efficiency and factors such as compatibility with the entire system architecture. Some commonly used encryption protocols and algorithms include Advanced Encryption Standard (AES), RSA encryption, SSL and TLS encryption.

在電信認證服務系統100中,裝置安全模組140實施定期安全更新和掃描,其旨在維護用戶之行動通訊裝置的安全和完整性。裝置安全模組140負責實施定期安全更新和掃描,確保行動通訊裝置對潛在威脅和漏洞保持防護。裝置安全模組140可以進行安全更新,以確保用戶的行動通訊裝置定期更新最新的安全補丁和固件更新,解決已知漏洞,提高設備的整體安全性。此外,裝置安全模組140在用戶之行動通訊裝置上強制實施定期的防病毒掃描,檢測和刪除任何可能危及多重認證流程或生物特徵認證模組120收集的生物特徵資料完整性的惡意軟件、病毒或其他惡意軟體。此外,裝置安全模組140還可認證用戶的行動通訊裝置是否符合所需的安全標準和政策,例如加密設置、密碼複雜度或應用程式白名單,確保認證流程的安全環境。 In the telecommunications authentication service system 100, the device security module 140 implements regular security updates and scans, which are designed to maintain the security and integrity of the user's mobile communication device. The device security module 140 is responsible for implementing regular security updates and scanning to ensure that the mobile communication device remains protected against potential threats and vulnerabilities. The device security module 140 can perform security updates to ensure that the user's mobile communication device is regularly updated with the latest security patches and firmware updates to resolve known vulnerabilities and improve the overall security of the device. In addition, the device security module 140 enforces regular anti-virus scanning on the user's mobile communication device to detect and remove any malware or viruses that may compromise the multi-factor authentication process or the integrity of the biometric data collected by the biometric authentication module 120 or other malware. In addition, the device security module 140 can also authenticate whether the user's mobile communication device complies with required security standards and policies, such as encryption settings, password complexity, or application whitelisting, to ensure a secure environment for the authentication process.

風險基礎認證模組150是通過適應用戶的行為和交易模式來增強多因素認證過程的安全性,其收集並分析用戶的活動資料,例如登錄時間、交易類型和設備使用模式,以識別可能的風險和異常情況。在風險基礎認證模組150資料收集和分析過程中,是從各種來源收集資料,例如用戶的行動通訊裝置、服務提供者和外部資料庫,以建立用戶行為和交易模式的全面概要。而且,風險基礎認證模組150還可採用機器學習算法和人工智能技術來分析收集的資料,並識別模式、趨勢和異常情況,使系統能夠根據感知到的風險動態調整其認證要求。之後,基於對用戶行為和交易模式的分析風險基礎認證模組150為每個活動分配風險評分,這用於確定特定交易或會話所需的適當認證級別。 The risk-based authentication module 150 enhances the security of the multi-factor authentication process by adapting to the user's behavior and transaction patterns. It collects and analyzes user activity data, such as login time, transaction type and device usage pattern, to identify possible risks. and abnormal situations. During the risk-based authentication module 150 data collection and analysis process, data is collected from various sources, such as users' mobile communication devices, service providers and external databases, to build a comprehensive profile of user behavior and transaction patterns. Furthermore, the risk-based certification module 150 can also use machine learning algorithms and artificial intelligence technology to analyze the collected data and identify patterns, trends and anomalies, allowing the system to dynamically adjust its certification requirements based on perceived risks. The risk-based authentication module 150 then assigns a risk score to each activity based on analysis of user behavior and transaction patterns, which is used to determine the appropriate authentication level required for a particular transaction or session.

此外,風險基礎認證模組150會根據辨識到的風險動態調整身份認證要求,提供更安全和用戶友善的身份認證體驗。這種動態調整例如為根據特定活動所 關聯的風險分數,或會考慮到環境因素,例如用戶的位置、設備或網路,以確保更有針對性和有效的安全反應。 In addition, the risk-based authentication module 150 will dynamically adjust identity authentication requirements based on identified risks, providing a more secure and user-friendly identity authentication experience. This dynamic adjustment is, for example, based on specific activities The associated risk score may take into account environmental factors, such as the user's location, device or network, to ensure a more targeted and effective security response.

風險基礎認證模組150與生物特徵認證模組120密切整合,以便根據檢測到的風險進行無縫的適應性身份認證。當風險基礎認證模組檢測到用戶行為和交易模式中存在潛在風險或異常時,它可以提示用戶提供生物特徵資料,然後由生物特徵認證模組120進行收集、存儲和認證。這種適應性身份認證過程利用了生物特徵資料的優勢,提供了額外的安全層,增強了多重認證的整體效力。透過收集和分析用戶行為和交易模式、動態調整身份認證要求以及與生物識別認證模組的整合,風險基礎認證模組150顯著增強了電信認證服務系統的安全性和效力。 The risk-based authentication module 150 is closely integrated with the biometric authentication module 120 for seamless adaptive authentication based on detected risks. When the risk-based authentication module detects potential risks or anomalies in user behavior and transaction patterns, it can prompt the user to provide biometric information, which is then collected, stored, and authenticated by the biometric authentication module 120. This adaptive authentication process takes advantage of biometric data, providing an additional layer of security and enhancing the overall effectiveness of multi-factor authentication. By collecting and analyzing user behavior and transaction patterns, dynamically adjusting identity authentication requirements, and integrating with biometric authentication modules, the risk-based authentication module 150 significantly enhances the security and effectiveness of the telecommunications authentication service system.

請同時參照圖1與圖2,圖2所繪示本新型之用戶、電信認證服務系統、服務提供者的應用示意圖。電信認證服務系統100由於包括多重認證模組110、生物特徵認證模組120、加密模組130、裝置安全模組140和風險基礎認證模組150可替用戶10及各種服務提供者20所提供的線上服務和應用程式加強安全性。在圖2中,用戶10可以為個人所使用的行動通訊裝置,服務提供者20可以為提供服務的伺服器或伺服器群組。以下,將介紹部分應用範例: Please refer to Figure 1 and Figure 2 at the same time. Figure 2 illustrates an application diagram of users, telecommunications authentication service systems, and service providers of the present invention. The telecommunications authentication service system 100 includes a multi-factor authentication module 110, a biometric authentication module 120, an encryption module 130, a device security module 140 and a risk-based authentication module 150, which can be used for users 10 and various service providers 20. Enhanced security of online services and applications. In FIG. 2 , the user 10 may be a mobile communication device used by an individual, and the service provider 20 may be a server or server group that provides services. Below, some application examples will be introduced:

1.線上銀行和金融服務:電信認證服務系統100非常適用於保障線上銀行和金融服務的安全性,其中保護用戶隱私資料和交易安全至關重要。透過電信認證服務系統100,銀行和金融機構可確保為客戶提供一個安全的環境,以便存取帳戶資訊、轉移資金、付款和執行其他線上銀行業務。生物特徵認證模組120和風險基礎認證模組150的整合提供了額外的安全層,允許基於用戶行為和交易模式的適應性認證。 1. Online banking and financial services: The telecommunications authentication service system 100 is very suitable for ensuring the security of online banking and financial services, where protecting user privacy information and transaction security is crucial. Through the telecommunications authentication service system 100, banks and financial institutions can ensure a secure environment for customers to access account information, transfer funds, make payments and perform other online banking services. The integration of the biometric authentication module 120 and the risk-based authentication module 150 provides an additional layer of security, allowing for adaptive authentication based on user behavior and transaction patterns.

2.電子商務和零售平台:電子商務和零售平台也可從電信認證服務系統100提供的增強安全性中受益。透過實施該電信認證服務系統100,電子商務和零售 平台可在線上購物過程中保護客戶數據,例如付款資料和個人詳細資料。多重認證模組110確保客戶必須提供至少兩種不同形式的認證,其中一種是生物特徵認證模組120的生物特徵數據,從而大大降低未經授權的訪問和欺詐風險。風險基礎認證模組150進一步通過根據客戶的行為和交易模式動態調整認證要求,增強了安全性。 2. E-commerce and retail platforms: E-commerce and retail platforms can also benefit from the enhanced security provided by the telecommunications authentication service system 100. By implementing the telecommunications authentication service system 100, e-commerce and retail The platform protects customer data, such as payment information and personal details, during the online shopping process. The multi-factor authentication module 110 ensures that the customer must provide at least two different forms of authentication, one of which is the biometric data of the biometric authentication module 120, thereby greatly reducing the risk of unauthorized access and fraud. The Risk Based Authentication Module 150 further enhances security by dynamically adjusting authentication requirements based on customer behavior and transaction patterns.

3.安全的電子郵件和通訊服務:電信認證服務系統100也可用於保障電子郵件和通訊服務的安全,確保傳輸的數據保持機密性和完整性。通過電信認證服務系統100,服務提供者可以提供端到端加密、多重認證以及基於用戶行為和風險因素的適應性認證。用戶可以安全地訪問他們的電子郵件和通訊服務,並且對於他們的數據受到保護,免受未經授權訪問和潛在威脅,感到相當有信心。 3. Secure email and communication services: The telecommunications authentication service system 100 can also be used to ensure the security of email and communication services, ensuring that the confidentiality and integrity of transmitted data are maintained. Through the telecommunications authentication service system 100, service providers can provide end-to-end encryption, multi-factor authentication, and adaptive authentication based on user behavior and risk factors. Users can access their email and messaging services securely and feel confident that their data is protected from unauthorized access and potential threats.

以上範例展示了電信認證服務系統100在提供廣泛的在線服務和應用程序的增強安全性方面的多功能性和效能。通過結合多重認證模組110、生物特徵認證模組120、加密模組130、裝置安全模組140和風險基礎認證模組150,電信認證服務系統100為各個行業和部門提供了全面且適應性的安全解決方案。 The above examples demonstrate the versatility and effectiveness of the telecommunications authentication service system 100 in providing enhanced security for a wide range of online services and applications. By combining the multi-factor authentication module 110, the biometric authentication module 120, the encryption module 130, the device security module 140 and the risk-based authentication module 150, the telecommunications authentication service system 100 provides comprehensive and adaptable solutions for various industries and departments. Security solutions.

雖然本新型已以較佳實施例揭露如上,然其並非用以限定本新型,任何所屬技術領域中具有通常知識者,在不脫離本新型之精神和範圍內,當可作些許之更動與潤飾,因此本新型之保護範圍當視後附之申請專利範圍所界定者為準。 Although the present invention has been disclosed above in terms of preferred embodiments, they are not intended to limit the present invention. Anyone with ordinary knowledge in the technical field may make slight changes and modifications without departing from the spirit and scope of the present invention. , therefore, the scope of protection of this new model shall be subject to the scope of the patent application attached.

100:電信認證服務系統 100:Telecom authentication service system

110:多重認證模組 110:Multiple authentication module

120:生物特徵認證模組 120:Biometric authentication module

130:加密模組 130: Encryption module

140:裝置安全模組 140:Device security module

150:風險基礎認證模組 150: Risk based certification module

Claims (6)

一種電信認證服務系統,與多個用戶的行動通訊裝置及至少一服務提供者電性連接,該電信認證服務系統包括:一多重認證模組,設置為進行多重認證過程,以要求該用戶提供至少兩種不同的認證方式,其中一種是生物特徵資料;一加密模組,與所述用戶的該行動通訊裝置及該服務提供者電性連接,該加密模組用於保護該用戶的該行動通訊裝置和該服務提供者之間的通信,保護在多重認證過程中傳輸的敏感資料;一裝置安全模組,電性連接至該加密模組,該裝置安全模組設置為對該用戶的行動通訊裝置進行定期安全更新和掃描;及一風險基礎認證模組,電性連接至該加密模組,該風險基礎認證模組用於分析該用戶的行為和交易模式,以識別潛在的風險,必要時提示該用戶提供至少一額外認證因素;其中,該多重認證模組包括一生物特徵認證模組,該生物特徵認證模組設置為收集、儲存和認證用戶的該生物特徵資料,且該多重認證模組電性連接至該加密模組。 A telecommunications authentication service system electrically connected to mobile communication devices of multiple users and at least one service provider. The telecommunications authentication service system includes: a multi-authentication module configured to perform a multi-authentication process to require the user to provide At least two different authentication methods, one of which is biometric data; an encryption module electrically connected to the user's mobile communication device and the service provider, the encryption module is used to protect the user's actions Communication between the communication device and the service provider protects sensitive information transmitted during the multi-factor authentication process; a device security module is electrically connected to the encryption module, and the device security module is configured to act on the user The communication device performs regular security updates and scans; and a risk-based authentication module is electrically connected to the encryption module. The risk-based authentication module is used to analyze the user's behavior and transaction patterns to identify potential risks, if necessary When prompting the user to provide at least one additional authentication factor; wherein the multi-factor authentication module includes a biometric authentication module, the biometric authentication module is configured to collect, store and authenticate the biometric information of the user, and the multi-factor authentication The module is electrically connected to the encryption module. 如請求項1所述的電信認證服務系統,其中該多重認證模組設置為要求該用戶提供以下組合:一第一特徵資料,是選自由一密碼、一個人身分識別碼、及一安全問題所組成的群組; 一第二特徵資料,是選自由一物理令牌、一行動通訊裝置相關認證、及一加密金鑰所組成的群組;及一第三特徵資料,是該用戶的至少一生物特徵資料,由該生物特徵認證模組收集。 The telecommunications authentication service system as described in claim 1, wherein the multi-authentication module is configured to require the user to provide the following combination: a first characteristic information selected from a password, a personal identification code, and a security question. group; a second characteristic data, selected from the group consisting of a physical token, a mobile communication device related authentication, and an encryption key; and a third characteristic data, which is at least one biometric data of the user, consisting of The Biometric Authentication Module Collection. 如請求項1或請求項2所述的電信認證服務系統,其中該生物特徵認證模組設置為收集和認證從選自由指紋、臉部識別、語音識別和虹膜識別所組成的群組中的生物特徵資料。 The telecommunications authentication service system as described in claim 1 or claim 2, wherein the biometric authentication module is configured to collect and authenticate biometrics selected from the group consisting of fingerprints, facial recognition, voice recognition and iris recognition. Characteristic data. 如請求項1所述的電信認證服務系統,其中該加密模組利用端對端加密來保護該用戶的該行動通訊裝置和該服務提供者之間的通訊。 The telecommunications authentication service system of claim 1, wherein the encryption module uses end-to-end encryption to protect communications between the user's mobile communication device and the service provider. 如請求項1所述的電信認證服務系統,其中該風險基礎認證模組設置為根據識別出的至少一潛在風險,包括一不尋常的用戶行為或一不規則的交易模式,提示用戶提供額外認證因素。 The telecommunications authentication service system as described in claim 1, wherein the risk-based authentication module is configured to prompt the user to provide additional authentication based on at least one potential risk identified, including an unusual user behavior or an irregular transaction pattern. factor. 如請求項1或請求項5所述的電信認證服務系統,其中該額外認證因素包括由該生物特徵認證模組認證的生物特徵資料。 The telecommunications authentication service system according to claim 1 or claim 5, wherein the additional authentication factor includes biometric information authenticated by the biometric authentication module.
TW112205403U 2023-05-30 2023-05-30 Telecommunication authentication service system TWM648486U (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
TW112205403U TWM648486U (en) 2023-05-30 2023-05-30 Telecommunication authentication service system
JP2023002658U JP3243831U (en) 2023-05-30 2023-07-25 Telephone authentication service system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW112205403U TWM648486U (en) 2023-05-30 2023-05-30 Telecommunication authentication service system

Publications (1)

Publication Number Publication Date
TWM648486U true TWM648486U (en) 2023-11-21

Family

ID=88021158

Family Applications (1)

Application Number Title Priority Date Filing Date
TW112205403U TWM648486U (en) 2023-05-30 2023-05-30 Telecommunication authentication service system

Country Status (2)

Country Link
JP (1) JP3243831U (en)
TW (1) TWM648486U (en)

Also Published As

Publication number Publication date
JP3243831U (en) 2023-09-22

Similar Documents

Publication Publication Date Title
US11290464B2 (en) Systems and methods for adaptive step-up authentication
EP3014836B1 (en) Method, communication system and computer program product for biometric authentication and authorization
Parmar et al. A comprehensive study on passwordless authentication
US20140258718A1 (en) Method and system for secure transmission of biometric data
Alqubaisi et al. Should we rush to implement password-less single factor FIDO2 based authentication?
ArunPrakash et al. Biometric encoding and biometric authentication (BEBA) protocol for secure cloud in m-commerce environment
Boonkrong et al. Methods and threats of authentication
Papaioannou et al. User authentication and authorization for next generation mobile passenger ID devices for land and sea border control
Karim et al. Choosing the right MFA method for online systems: A comparative analysis
Karim et al. Online Banking User Authentication Methods: A Systematic Literature Review
Pampori et al. Securely eradicating cellular dependency for e-banking applications
US20220407693A1 (en) Method and device for secure communication
JP3243831U (en) Telephone authentication service system
Nwogu Improving the security of the internet banking system using three-level security implementation
Waheed et al. Secure login protocols: An analysis on modern attacks and solutions
Nashwan et al. Mutual chain authentication protocol for SPAN transactions in Saudi Arabian banking
Yasin et al. Enhancing anti-phishing by a robust multi-level authentication technique (EARMAT).
You et al. A study on the two-channel authentication method which provides two-way authentication in the Internet banking environment
Kumari et al. Secure Credit or Debit Card Transaction Using Alert messages and OTP to prevent phishing attacks
Hari et al. Enhancing security of one time passwords in online banking systems
Prasad A Comparative Study of Passwordless Authentication
Rivers et al. A Study on Cyber Attacks and Vulnerabilities in Mobile Payment Applications
Alhanahnah et al. Boosting usability for protecting online banking applications against APTs
EP2860935B1 (en) A computer implemented method to prevent attacks against authorization systems and computer programs products thereof
Matei-Dimitrie Multi-factor authentication. An extended overview